用流程挖掘提升异常检测系统可解释性,精准分级告警。
Enhancing Anomaly-Based Intrusion Detection Systems with Process Mining

- 通过流程挖掘分析数据包序列,生成基于过程的告警解释。
- 在保留99.94%召回率的同时,实现99.99%精确率,有效过滤误报。
- 适合需要高可信度和可解释性的网络安全场景。
基于异常的入侵检测系统(IDS)能有效防御网络系统攻击。尽管深度学习型IDS表现良好,但其黑箱结构导致可信度受限。现有可解释技术虽能解读告警,却缺乏基于数据包序列的过程级解释。本文提出一种结合流程挖掘的方法,为异常型IDS提供基于过程的告警严重性评分与解释,优先处理关键告警,保持对网络行为的可见性,并允许误判的正常流量通过以减少干扰。我们在公开的USB-IDS-TC数据集上验证,该方法能区分低至极高严重性的告警,在保持最高99.94%召回率和99.99%精确率的前提下,有效剔除虚假告警,并为真实告警提供不同程度的严重性分级。
原文摘要 · Abstract (English)
Anomaly-based Intrusion Detection Systems (IDSs) ensure protection against malicious attacks on networked systems. While deep learning-based IDSs achieve effective performance, their limited trustworthiness due to black-box architectures remains a critical constraint. Despite existing explainable techniques offering insight into the alarms raised by IDSs, they lack process-based explanations grounded in packet-level sequencing analysis. In this paper, we propose a method that employs process mining techniques to enhance anomaly-based IDSs by providing process-based alarm severity ratings and explanations for alerts. Our method prioritizes critical alerts and maintains visibility into network behavior, while minimizing disruption by allowing misclassified benign traffic to pass. We apply the method to the publicly available USB-IDS-TC dataset, which includes anomalous traffic affected by different variants of the Slowloris DoS attack. Results show that our method is able to discriminate between low- to very-high-severity alarms while preserving up to 99.94% recall and 99.99% precision, effectively discarding false positives while providing different degrees of severity for the true positives.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。